The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of
The USB device-side CDC NCM class control-to-host handler usbd_cdc_ncm_cth in subsys/usb/device_next/class/usbd_cdc_ncm.
The USB DFU class implementation in Zephyr's new (experimental) device_next USB device stack contains a NULL pointer der
The Realtek BEE Bluetooth HCI driver's send callback, bt_hci_bee_send() in drivers/bluetooth/hci/hci_bee.c, violated the
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site
The Bluetooth HCI driver for Bouffalo Lab on-chip BLE controllers (BL60x/BL70x/BL61x), bt_bflb_send() in drivers/bluetoo
A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a mali
A flaw was found in wildfly-core. A remote user authenticated as an administrative user can inject a malformed payload i
Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP, an authenticated attacker co
SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. A
SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations. D
SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under spec
SAP Approuter does not enforce cross-site request forgery protection on the authentication flow by default. An unauthent
A malicious or compromised OData service could disclose sensitive authentication information and inject untrusted data i
SAP BusinessObjects Business Intelligence Platform (Admin Tools) does not perform sufficient authorization check on cer
SAPUI5 allows a key user with content adaptation privileges to inject malicious script content into persisted applicatio
Due to an SQL Injection vulnerability in SAP Social intelligence, an authenticated attacker could directly inject an SQL
Reprocess Bank Statement Items in SAP S/4HANA does not perform the necessary authorization checks for authenticated user
SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with low privileges could s
SAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low privileges
SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to upload a speci
SAP ABAP Platform allows an unauthenticated user to send a specially crafted request to an internal component. This coul
SAP Manufacturing Integration and Intelligence (MII) does not perform necessary authorization check on certain applicati
SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard) allows a low-privi
SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could
WebSocket of SAP Approuter does not perform sufficient authorization checks in certain functionality. An attacker with l
SAP NetWeaver Application Server ABAP and ABAP Platform allow an attacker with high privileges to bypass missing securit
SAP NetWeaver Application Server Java (Adobe Document Service) uses outdated open source cryptographic and data transfer
SAP SAPSPrint Service has memory corruption vulnerabilities in the handling of certain commands. An unauthenticated atta
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti
A type mismatch vulnerability was found in QEMU's vhost inflight migration VMState handling. The destination buffer size
npm-check-updates through 23.0.2, fixed in commit b554b84, contains a terminal escape sequence injection vulnerability t
Sucuri Security WordPress plugin through version 2.7.3 contains a path traversal vulnerability in the pageIntegritySubmi
CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.3.0, CyberChef's pretty-rec
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.109.0 and 16.20.0, the get_tax_template
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the add_ac function
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the send_auto_email
SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cross-site scripting vulnerability in the SQText dashb
A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repository. Th
A flaw was found in the `odh-model-controller`. An authenticated user with permissions to create custom resources can ex
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.one in apps/dokploy/server/
FlyEnv before 4.18.0 fails to sanitize HTML from markdown rendering and AI chat content passed to Vue v-html directives.
Spacebar Server before commit 8d126f4 contains a cross-channel message deletion vulnerability in the single-delete and b
Typemill CMS version 2.x contains a persistent cross-site scripting vulnerability in the Markdown parser extension that
OP-TEE OS through 4.10.0, fixed in commit 7b8b494, contains a buffer underwrite vulnerability in the RSA NOPAD encrypt a
OP-TEE OS through 4.10.0, fixed in commit 8794043, contains a use-after-free vulnerability in the Trusted Application lo
OP-TEE OS through 4.10.0, fixed in commit 0aadfc2, contains a null pointer dereference vulnerability in the Widevine pse
CyberPanel 2.4.3, fixed in commit eca0c3c, contains an arbitrary file read vulnerability in the file manager component t
Frequently Asked Questions
What does MEDIUM severity mean for CVEs?
CVSS 4.0–6.9 — moderate vulnerabilities that may require specific conditions or user interaction to exploit
How many medium severity CVEs exist?
There are 164,190 CVE records rated MEDIUM in our database. Of these, 101 are listed in CISA's Known Exploited Vulnerabilities catalog.
How should I prioritize medium severity vulnerabilities?
MEDIUM severity vulnerabilities should be addressed as part of regular patching cycles. Prioritize those with high EPSS scores or that affect critical systems. CyberStrike helps you assess real-world exploitability beyond CVSS scores.
Detect MEDIUM Vulnerabilities
CyberStrike scans your infrastructure and detects medium severity vulnerabilities in real time.
Get Started